CVE-2022-27924

CVE Published 2022-04-21
Related CWE(s) CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Related Vendor(s) zimbra
Related Product(s) collaboration
Exploitation Reported (CISA KEV) 2022-08-04
CVSS 3 Base Score 7.5 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Threat Reports Related to CVE-2022-27924

Report

RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale

This report from Recorded Future's Insikt Group outlines activity by the Red Hotel intrusion set. RedHotel is identified as a prominent Chinese ...

Associated CAPEC Patterns

References